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In the Claims 

Please cancel claims 33-36 and 71-75 without prejudice. 

Please amend claims 20-25, 27, 29, 37, 39, 41, 61, and 64 as shown herein. 

Claims 1-32 and 37-70 are pending and are listed following: 

1. (original) A network system, comprising: 
a first device to maintain an original resource; 

a second device to maintain a replica resource remotely from the first 
device, the replica resource being replicated from the original resource; 

memory to store a cached descriptor corresponding to the original resource; 

a security component to determine whether the replica resource will pose a 
security risk to the second device upon receipt of a request for the replica resource, 
the security component: 

formulating a descriptor corresponding to the replica resource and 

comparing the formulated descriptor with the cached descriptor; and 

if the formulated descriptor and the cached descriptor are not 

equivalent, formulating a second descriptor corresponding to the original 

resource and comparing the formulated descriptor with the second 

descriptor. 

2. (original) A network system as recited in claim 1, wherein the 
security component determines that the replica resource is not a security risk if the 
formulated descriptor and the cached descriptor are equivalent. 
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3. (original) A network system as recited in claim 1, wherein, if the 
formulated descriptor and the cached descriptor are not equivalent, and if the 
formulated descriptor and the second descriptor are equivalent, the security 
component determines that the replica resource is not a security risk. 

4. (origina!) A network system as recited in claim 1, wherein, if the 
formulated descriptor and the cached descriptor are not equivalent, and if the 
formulated descriptor and the second descriptor are equivalent, the security 
component determines that the replica resource is not a security risk, and the 
cached descriptor is replaced with the second descriptor. 

5. (original) A network system as recited in claim 1, wherein, if the 
formulated descriptor and the cached descriptor are not equivalent, and if the 
formulated descriptor and the second descriptor are not equivalent, the security 
component determines that the replica resource is a security risk, and the replica 
resource is replaced with a copy of the original resource. 

6. (original) A network system as recited in claim 1, wherein, if the 
formulated descriptor and the cached descriptor are not equivalent, and if the 
formulated descriptor and the second descriptor are not equivalent, the security 
component determines that the replica resource is a security risk, the replica 
resource is replaced with a copy of the original resource, and the cached descriptor 
is replaced with the second descriptor. 
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7. (original) A network system as recited in claim 1, wherein the 
security component formulates the cached descriptor when the original resource is 
replicated to create the replica resource. 

8. (original) A network system as recited in claim 1, wherein the 
security component is configured to determine whether the request will pose a 
security risk to the second device. 

9. (original) A network system as recited in claim 8, wherein the 
request designates a resource locator. 

10. (original) A network system as recited in claim 8, wherein the 
request designates a resource locator having a resource 'path, the resource path 
identifying a location of the replica resource, and wherein the security component 
determines that the request is not a security risk if the resource path does not 
exceed a maximum number of characters. 

11. (original) A network system as recited in claim 8, wherein the 
request designates a resource locator having a plurality of arguments, and wherein 
the security component determines that the request is not a security risk if 
individual arguments do not exceed a maximum number of characters, and if a 
total number of characters defining all of the arguments do not exceed a maximum 
number of characters. 
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12. (original) A network system as recited in claim 8, wherein the 
request designates a resource locator having a resource identifier, and wherein the 
security component determines that the request is not a security risk if the resource 
identifier has a valid file extension. 



13* (original) A network system as recited in claim 1, wherein: 

the request designates a resource locator having a resource path and one or 
more arguments, the resource path identifying a location of the replica resource 
and the resource path having a resource identifier; 

the security component is configured to determine whether the request will 
pose a security risk to the second device; 

the security component determines that the request is not a security risk if: 
the resource path does not exceed a maximum number of characters; 
individual arguments do not exceed a maximum number of 

characters; 

a total number of characters defining all of the arguments do not 
exceed a maximum number of characters; and 

the resource identifier has a valid file extension. 
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14. (original) A network server, comprising: 

a server component to receive a request for a resource maintained on the 
network server and, in response to the request, implement security policies to 
prevent unauthorized access to the resource; and 

a security component that is registerable with the server component during 
ran-time to determine whether the request will pose a security risk to the network 
server. 

15. (original) A network server as recited in claim 14, wherein, if the 
security component determines that the request will pose a security risk, the 
security component redirects the request to indicate that the resource is not 
available. 

16. (original) A network server as recited in claim 14, wherein the 
request designates a resource locator having a resource path, the resource path 
identifying a location of the resource, and wherein the security component 
determines that the request is not a security risk if the resource path does not 
exceed a maximum number of characters. 
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17. (original) A network server as recited in claim 14, wherein the 
request designates a resource locator having a plurality of arguments, and wherein 
the security component determines that the request is not a security risk if 
individual arguments do not exceed a maximum number of characters, and if a 
total number of characters defining all of the arguments do not exceed a maximum 
number of characters. 

18. (original) A network server as recited in claim 14, wherein the 
request designates a resource locator having a resource identifier, and wherein the 
security component determines that the request is not a security risk if the resource 
identifier has a valid file extension. 

19. (original) A network server as recited in claim 14, wherein: 

the request designates a resource locator having a resource path and one or 
more arguments, the resource path identifying a location of the resource and the 
resource path having a resource identifier; 

the security component determines that the request is not a security risk if: 
the resource path does not exceed a maximum number of characters; 
individual arguments do not exceed a maximum number of 
characters; 

a total number of characters defining all of the arguments do not 
exceed a maximum number of characters; and 

the resource identifier has a valid file extension. 
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20. (currently amended) A network server system , comprising: 

a server component in a network server to receive a request for a resource 
maintained on the network server and, in response to the request, implement 
security policies to prevent unauthorized access to the resource; and 

a security component that is in a computing device remote to the network 
server and registerable with the server component during run-time to determine 
whether the resource will pose a security risk to the network server upon receipt of 
the request. 

21. (currently amended) A network server system as recited in 
claim 20, wherein, if the security component determines that the resource will 
pose a security risk, the security component redirects the request to indicate that 
the resource is not available. 

22. (currently amended) A network server system as recited in 
claim 20, wherein the security component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; and 

determines that the resource is not a security risk if the formulated 
descriptor and the cached descriptor are equivalent. 
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23. (currently amended) A network server system as recited in 
claim 20, wherein the security component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource maintained 
on a file server remotely located from the network server, the resource being 
replicated from the original resource; 

compares the formulated descriptor with the second descriptor; and 
determines that the resource is not a security risk if the formulated 
descriptor and the second descriptor are equivalent. 
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24, (currently amended) A network server system as recited in 
claim 20, wherein the security component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested: 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource maintained 
on a file server remotely located from the network server, the resource being 
replicated from the original resource; 

compares the formulated descriptor with the second descriptor; 

if the formulated descriptor and the second descriptor are not equivalent, 
initiates that the resource stored on the network server be replaced with a copy of 
the original resource maintained on the file server; and 

initiates that the cached descriptor be replaced with the second descriptor. 
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25. (currently amended) A network server, comprising: 

an Internet server to receive a request for a resource maintained on the 
network server and, in response to the request, implement security policies to 
prevent unauthorized access to the resource; 

a security component that is registerable with the Internet server during 
rjn-tim.e, the security com.ponent having: 

a validation component to determine whether the request will pose a 

security risk to the network server by determining if a total number of 

characters defining all of the arguments of the request exceeds a maximum 

number of characters ; and 

an integrity verification component to determine whether the 

resource will pose a security risk to the network server upon receipt of the 

request. 

26. (original) A network server as recited in claim 25, wherein the 
request designates a resource locator having a resource path, the resource path 
identifying a location of the resource, and wherein the validation component 
determines that the request is not a security risk if the resource path does not 
exceed a maximum number of characters. 
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27. (currently amended) A network server as recited in claim 25, 
wherein the request designates a resource locator having a plurality of arguments, 
and wherein the validation component determines that the request is not a security 
risk if individual arguments do not exceed a maximum number of characters^and 
if a total numb e r of characters d e fining all of th e argum e nts do not e xc ee d a 
maximum num.b e r of charact e rs . 

28. (original) A network server as recited in claim 25, wherein the 
request designates a resource locator having a resource identifier, and wherein the 
validation component determines that the request is not a security risk if the 
resource identifier has a valid file extension. 
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29. (currently amended) A network server as recited in claim 25, 
wherein: 

the request designates a resource locator having a resource path and one or 
more arguments, the resource path identifying a location of the resource and the 
resource path having a resource identifier; 

the validation component determines that the request is not a security risk 

if: 

the resource path does not exceed a maximum number of characters; 
individual arguments do not exceed a maximum number of 
characters; and 

a total numb e r of charact e rs d e fining all of th e argum e nts do not 
exc ee d a maximum numb e r of charact e rs; and 

the resource identifier has a valid file extension. 

30. (original) A network server as recited in claim 25, wherein the 
integrity verification component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; and 

determines that the resource is not a security risk if the formulated 
descriptor and the cached descriptor are equivalent. 
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31. (original) A network server as recited in claim 25, wherein the 
integrity verification component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource maintained 
on a file server remotely located from the network server, the resource being 
replicated from the original resource; 

compares the formulated descriptor with the second descriptor; and 
determines that the resource is not a security risk if the formulated 
descriptor and the second descriptor are equivalent. 
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32. (original) A network server as recited in claim 25, wherein the 
integrity verification component: 

formulates a descriptor corresponding to the resource; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource maintained 
on a file server remotely located from the network server, the resource being 
replicated from the original resource; 

compares the formulated descriptor with the second descriptor; 

if the formulated descriptor and the second descriptor are not equivalent, 
initiates that the resource stored on the network server be replaced with a copy of 
the original resource maintained on the file server; and 

initiates that the cached descriptor be replaced with the second descriptor. 

33-36. canceled 
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37. (currently amended) One or more computer readable media 
containing a security application, comprising: 

a validation component to determine whether a request for a resource poses 
a security risk by determining if a total number of characters defminR all of the 
arguments of the request exceeds a maximum number of characters : and 

an integrity verification com.ponent to determine whether the resource poses 
a security risk. 

38. (original) Computer readable media as recited in claim 37, 
wherein the request designates a resource locator having a resource path, the 
resource path identifying a location of the resource, and wherein the validation 
component determines that the request is not a security risk if the resource path 
does not exceed a maximum number of characters. 

39. (currently amended) Computer readable media as recited in 
claim 37, wherein the request designates a resource locator having a plurality of 
arguments, and wherein the validation component determines that the request is 
not a security risk if individual arguments do not exceed a maximum number of 
characters , and if a total numb e r of charact e rs d e fining all of th e argum e nts do not 
e xc ee d a maximum numb e r of charact e rs . 
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40. (original) Computer readable media as recited in claim 37, 
wherein the request designates a resource locator having a resource identifier, and 
wherein the validation component determines that the request is not a security risk 
if the resource identifier has a valid file extension. 

41. (currently amended) Computer readable media as recited in 
claim 37, wherein: 

the request designates a resource locator having a resource path and one or 
more arguments, the resource path identifying a location of the resource and the 
resource path having a resource identifier; 

the validation component determines that the request is not a security risk 

if: 

the resource path does not exceed a maximum number of characters; 
individual arguments do not exceed a maximum number of 
characters; and 

a total numb e r of charact e rs d e fining all of th e argum e nts do not 
e xc ee d a maximum numb e r of charact e rs; and 

the resource identifier has a valid file extension. 
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42. (original) Computer readable media as recited in claim 37, 
wherein the integrity verification component: 

formulates a descriptor corresponding to the resource when the security 
application receives the request; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; and 

determines that the resource is not a security risk if the formulated 
descriptor and the cached descriptor are equivalent. 

43. (original) Computer readable media as recited in claim 37, 
wherein the integrity verification component: 

formulates a descriptor corresponding to the resource when the security 
application receives the request; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource remotely 
located, the resource being replicated from the original resource; 

compares the formulated descriptor with the second descriptor; and 
determines that the resource is not a security risk if the formulated 
descriptor and the second descriptor are equivalent. 
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44. (original) Computer readable media as recited in claim 37, 
wherein the integrity verification component: 

formulates a descriptor corresponding to the resource when the security 
application receives the request; 

compares the formulated descriptor with a cached descriptor, the cached 
descriptor corresponding to the resource and formulated when the resource is 
initially requested; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulates a second descriptor corresponding to an original resource remotely 
located, the resource being replicated from the original resource; 

compares the formulated descriptor with the second descriptor; 

if the formulated descriptor and the second descriptor are not equivalent, 
initiates that the resource be replaced with a copy of the original resource; and 

initiates that the cached descriptor be replaced with the second descriptor. 
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45. (original) A method, comprising: 

receiving a request for a replica resource stored on a computing device; 

formulating a descriptor corresponding to the replica resource; 

comparing the formulated descriptor with a cached descriptor 
corresponding to an original resource stored on a second computing device 
remotely located from the computing device, the replica resource being replicated 
from the original resource; 

determining that the replica resource does not pose a security risk if the 
formulated descriptor and the cached descriptor are equivalent; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulating a second descriptor corresponding to the original resource; 

comparing the formulated descriptor with the second descriptor; and 

determining that the replica resource does not pose a security risk if the 
formulated descriptor and the second descriptor are equivalent. 

46. (original) A method as recited in claim 45, fiirther comprising 
allowing the request if said determining that the replica resource does not pose a 
security risk to the computing device. 

47. (original) A method as recited in claim 45, further comprising 
redirecting the request to indicate that the replica resource is not available if 
determining that the replica resource poses a security risk to the computing device. 
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48. (original) A method as recited in claim 45, further comprising 
replacing the cached descriptor with the second descriptor if the formulated 
descriptor and the second descriptor are equivalent. 

49. (original) A method as recited in claim 45, further comprising 
replacing the replica resource with a copy of the original resource if the 
formulated descriptor and the cached descriptor are not equivalent, and if the 
formulated descriptor and the second descriptor are not equivalent. 

50. (original) A method as recited in claim 45, further comprising 
replacing the cached descriptor with the second descriptor if the formulated 
descriptor and the cached descriptor are not equivalent, and if the formulated 
descriptor and the second descriptor are not equivalent. 

51. (original) A method as recited in claim 45, further comprising 
formulating the cached descriptor when the original resource is replicated to create 
the replica resource. 

52. (original) A method as recited in claim 45, further comprising 
formulating the cached descriptor when the replica resource is initially requested. 

53. (original) A method as recited in claim 45, further comprising 
determining whether the request will pose a security risk. 
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54. (original) A method as recited in claim 45, further comprising: 
determining whether the request will pose a security risk; and 
redirecting the request to indicate that the replica resource is not available if 

determining that the request poses a security risk to the computing device. 

55. (original) A. m.ethod as recited in claim 45, wherein the request 
designates a resource locator having a resource path, the resource path identifying 
a location of the replica resource, and the method further comprising determining 
that the request does not pose a security risk if the resource path does not exceed a 
maximum number of characters. 

56. (original) A method as recited in claim 45, wherein the request 
designates a resource locator having a plurality of arguments, and the method 
further comprising determining that the request does not pose a security risk if 
individual arguments do not exceed a maximum number of characters, and if a 
total number of characters defining all of the arguments do not exceed a maximum 
number of characters. 

57. (original) A method as recited in claim 45, wherein the request 
designates a resource locator having a resource identifier, and the method further 
comprising determining that the request does not pose a security risk if the 
resource identifier has a valid file extension. 
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58. (original) A method as recited in claim 45, wherein: 

the request designates a resource locator having a resource path and one or 
more arguments, the resource path identifying a location of the replica resource 
and the resource path having a resource identifier; 

the method further comprising determining that the request does not pose a 
security risk if: 

the resource path does not exceed a maximum number of characters; 
individual arguments do not exceed a maximum number of 
characters; 

a total number of characters defining all of the arguments do not 
exceed a maximum number of characters; and 

the resource identifier has a valid file extension. 

59. (original) A computer-readable medium comprising computer 
executable instructions that, when executed, direct a computing system to perform 
the method of claim 45. 

60. (original) A computer-readable medium comprising computer 
executable instructions that, when executed, direct a computing system to perform 
the method of claim 58. 
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61. (currently amended) A method, comprising: 
receiving a request for a resource; 

implementing security policies to prevent unauthorized access to the 
resource; 

determining w^hether the request v^ill pose a security risk by determining if 
a total number of characters defining all of the arguments of the request exceeds a 
maximum number of characters : and 

determining whether the resource will pose a security risk if allowing the 
request. 

62. (original) A method as recited in claim 61, further comprising 
allowing the request for the resource if determining that the request does not pose 
a security risk and if determining that the resource does not pose a security risk. 

63. (original) A method as recited in claim 61, wherein the request 
designates a resource locator having a resource path, the resource path identifying 
a location of the resource, and the method further comprising determining that the 
request does not pose a security risk if the resource path does not exceed a 
maximum number of characters. 
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64. (currently amended) A method as recited in claim 61, wherein 
the request designates a resource locator having a pluraHty of arguments, and the 
method further comprising determining that the request does not pose a security 
risk if individual arguments do not exceed a maximum number of characters^^nd 
if a total numb e r of characters d e fining all of the argum e nts do not e xc ee d a 
maximum numb e r of charact e rs . 

65. (original) A method as recited in claim 61, wherein the request 
designates a resource locator having a resource identifier, and the method fiirther 
comprising determining that the request does not pose a security risk if the 
resource identifier has a valid file extension. 

66. (original) A method as recited in claim 6 1 , further comprising: 
formulating a descriptor corresponding to the resource; 

comparing the formulated descriptor with a cached descriptor 
corresponding to the resource and formulated when the resource is initially 
requested; and 

determining that the resource does not pose a security risk if the formulated 
descriptor and the cached descriptor are equivalent. 
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67. (original) A method as recited in claim 61, further comprising: 

formulating a descriptor corresponding to the resource; 

comparing the formulated descriptor with a cached descriptor 
corresponding to the resource and formulated when the resource is initially 
requested; 

determining that the resource does not pose a security risk if the formulated 
descriptor and the cached descriptor are equivalent; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulating a second descriptor corresponding to an original resource remotely 
located, the resource replicated from the original source; 

comparing the formulated descriptor with the second descriptor; and 

determining that the resource does not pose a security risk if the formulated 
descriptor and the second descriptor are equivalent. 
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68. (original) A method as recited in claim 61, further comprising: 
formulating a descriptor corresponding to the resource; 

comparing the formulated descriptor with a cached descriptor 
corresponding to the resource and formulated when the resource is initially 
requested; 

determining that the resource does not pose a security risk if the formulated 
descriptor and the cached descriptor are equivalent; 

if the formulated descriptor and the cached descriptor are not equivalent, 
formulating a second descriptor corresponding to an original resource remotely 
located, the resource replicated from the original resource; 

comparing the formulated descriptor with the second descriptor; and 

determining that the resource does not pose a security risk if the formulated 
descriptor and the second descriptor are equivalent; 

if the formulated descriptor and the second descriptor are not equivalent, 
replacing the resource with a copy of the original resource and replacing the 
cached descriptor with the second descriptor. 

69. (original) A computer-readable medium comprising computer 
executable instmctions that, when executed, direct a computing system to perform 
the method of claim 61 . 

70. (original) A computer-readable medium comprising computer 
executable instmctions that, when executed, direct a computing system to perform 
the method of claim 68. 
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